Computational Cluster Multi-Domain Access via Merged Authentication Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computational clusters face difficulties in configuring access to multiple domains, isolating users and services, and securing critical accounts across different domains, due to challenges in managing access and authentication.
Innovation Solution
A method and system using a ticket-based computer network authentication protocol to generate and merge keys for multiple domains, activating a system daemon to provide access, and authenticating cluster access requests across primary and secondary domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a computational cluster is configured for access to multiple domains, then the cluster can access users and services across different domains, but the complexity of managing access and authentication increases
Solution Approach 1:
The patent merges multiple domain credentials into a single credential store, allowing the computational cluster to access multiple domains using unified authentication mechanisms rather than managing separate credentials for each domain
Solution Approach 2:
The patent introduces an intermediary authentication service that mediates between the computational cluster and multiple domains, handling the complexity of cross-domain authentication while presenting a simplified interface to the cluster
2Adaptability or versatility
If domain credentials are stored for multiple domains, then the cluster can authenticate across domains, but the security risk of storing multiple sets of credentials increases
Solution Approach 1:
The patent extracts domain credentials from the computational cluster and stores them in a separate, dedicated credential store, isolating the security risk away from the cluster itself while maintaining authentication capabilities
Solution Approach 2:
The patent implements temporary, session-based credentials that are automatically invalidated after use, replacing the need to store long-term credentials for multiple domains and reducing the window of vulnerability
3Adaptability or versatility
If a system daemon is activated to manage multiple domain credentials, then authentication across domains is enabled, but the resource consumption increases
Solution Approach 1:
The system daemon implements periodic credential validation and rotation, actively managing credentials only when needed for authentication rather than continuously processing all domain access requests
Solution Approach 2:
The credential store is designed to automatically manage its own credentials through self-service mechanisms including automatic validation, rotation, and revocation, reducing the computational overhead on the system daemon
Data Source
AI summary
A computer-implemented method for managing computational cluster access to multiple domains includes generating, using a ticket-based computer network authentication protocol, a primary set of keys based on remote system access credentials for a primary domain and a secondary set of keys based on remote system access credentials for a secondary domain. The method includes merging the primary set of keys with the secondary set of keys to form a merged set of keys. The method further includes activating a system daemon to provide access to the primary domain and the secondary domain by a computational cluster based on the merged set of keys. The method further includes connecting, using the ticket-based computer network authentication protocol via the system daemon, a remote computing device of the primary domain and a remote computing device of the secondary domain to the computational cluster.


